Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

Britive Python SDK

Python client for the Britive API.

The SDK provides Python methods for Britive APIs. It generally passes values to the API for validation, but some methods combine related API operations or normalize responses for Python callers.

This package supports Python versions >= 3.10.

Installation

pip install britive

To install the current source from GitHub instead of PyPI, run:

pip install "git+https://github.com/britive/python-sdk.git"

Documentation

Method docstrings describe parameters, return values, and API-specific behavior.

Official API documentation can be found here: Britive API Documentation.

Authentication

The SDK accepts Britive API tokens, temporary bearer tokens, and workload federation tokens. Provide an API or bearer token in one of these ways:

  1. Passed directly into the class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_API_TOKEN.

To source a workload federation token, pass token_federation_provider to the Britive constructor. Supported providers include AWS, Azure managed identities, Bitbucket Pipelines, GCP, GitHub Actions, GitLab, and Spacelift.

Every token authenticates against a specific Britive tenant. Provide the tenant in one of these ways:

  1. Passed directly into the Britive class constructor.
  2. Injected as an environment variable into the execution context where this package is being run.

The environment variable name is BRITIVE_TENANT.

In order to obtain the tenant name, reference the Britive URL used to log into the UI.If the URL is https://example.britive-app.com then the tenant name will be example.

Pagination

All pagination is handled by the package. The caller will never have to deal with paginated responses.

Assumptions

  • The caller has access to an active Britive tenant.
  • The caller has a token for a user, service identity, or workload.
  • No assumptions are made about the operating system or file system.
  • The SDK does not persist responses unless a method accepts and receives an output file, such as audit_logs.logs.download_csv(output_file=...).

Resource Coverage

The SDK includes clients for these main Britive areas:

  • Access Broker
  • API tokens
  • Application management, including applications, profiles, accounts, permissions, and scans
  • Audit logs and audit log webhooks
  • Global settings, including notification mediums, firewall settings, and ITSM
  • Identity management, including users, service identities, AI identities, tags, and identity providers
  • My Access, My Approvals, My Requests, My Resources, and My Secrets
  • Reports
  • Secrets Manager
  • Security, including SAML, security policies, active sessions, and step-up authentication
  • System roles, policies, permissions, consumers, and actions
  • Workflows, notifications, and tasks

Proxies

The SDK uses Python requests to communicate with the Britive API. Configure an HTTP proxy through environment variables supported by requests.

  • HTTP proxies will be set via environment variables.
    • HTTP_PROXY
    • HTTPS_PROXY
    • NO_PROXY
    • http_proxy
    • https_proxy
    • no_proxy

Standard HTTP proxy URLs should be utilized.

Examples:

  • Unauthenticated Proxy: http://internalproxy.domain.com:8080
  • Authenticated Proxy: http://user:pass@internalproxy.domain.com:8080

Custom TLS Certificates

Configure custom TLS certificates through environment variables supported by requests.

  • Certificate bundles can be set via environment variables.
    • REQUESTS_CA_BUNDLE
    • CURL_CA_BUNDLE(used as a fallback)
    • PYBRITIVE_CA_BUNDLE(specific to the Britive Python SDK)

The values of these environment variables must be a path to a directory of certificates or a specific certificate.

Example:/path/to/certfile

Platform Examples

Linux/macOS

export REQUESTS_CA_BUNDLE="/usr/local/corp-proxy/cacert.pem"

Windows

PowerShell
$env:REQUESTS_CA_BUNDLE="C:\Users\User\AppData\Local\corp-proxy\cacert.pem"
Command Prompt
set"REQUESTS_CA_BUNDLE=C:\Users\User\AppData\Local\corp-proxy\cacert.pem"

Examples

Importing

This should be the only class that is required for import.

frombritive.britiveimportBritive

Optionally, the various exceptions that this package raises can be imported as well, e.g.

frombritiveimportexceptions

Then specific exception(s) could be referenced as demonstrated below:

try:
something()
exceptexceptions.TokenMissingError:
handle()

List All Users

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Provide Needed Authentication Information in the Script

frombritive.britiveimportBritiveimportjsonbritive=Britive(tenant='example', token='...') # source token and tenant locally (not from environment variables)print(json.dumps(britive.identity_management.users.list(), indent=2, default=str))

Create API Token for a Service Identity

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(
britive.identity_management.service_identity_tokens.create(service_identity_id='abc123'),
indent=2,
default=str,
))

Run a Report (JSON and CSV output)

frombritive.britiveimportBritiveimportjsonbritive=Britive() # source needed data from environment variablesprint(json.dumps(britive.reports.run(report_id='abc123'), indent=2, default=str))
withopen('file.csv', 'w') asf:
f.write(britive.reports.run(report_id='abc123', csv=True))

Create an application profile policy

The commands below will create a policy on a profile that allows user@domain.com to check out the profile but only if approver@domain.com approves that request within 10 minutes.

frombritive.britiveimportBritiveb=Britive()
policy=b.application_management.profiles.policies.build(
name='example',
users=['user@domain.com'],
approval_notification_medium='Email',
approver_users=['approver@domain.com'],
time_to_approve=10
)
b.application_management.profiles.policies.create(profile_id='...', policy=policy)

About

Python SDK for the Britive REST API

Topics

Resources

Contributing

Stars

7 stars

Watchers

4 watching

Forks

Releases

Used by

Contributors

Languages