- No guessing. Every endpoint/behavior claim needs evidence: app traffic, APK
smali/strings reference, or an ovoid-PHP commit. Otherwise mark it
BELUM TERVERIFIKASI+ TODO. - Tests stay offline. Never hit the real API; never require credentials. Use the
FakeHttpClientintests/conftest.py. - No credentials in the repo. Tokens, PINs, OTPs, device IDs — keep them in env vars.
- Conventional Commits (
feat:,fix:,docs:,test:,chore:).
pip install -e ".[dev]"
pytest
ruff check src tests && ruff format --check src tests
mypy srcThis SDK mirrors lintangtimur/ovoid. When porting:
- Keep method parity (
camelCasePHP →snake_casePython) and the same wire shapes. - Deliberate deviations (like the APK-verified header defaults) must cite
research/evidence and be noted inCHANGELOG.md. - Update
docs/services/<name>.mdand add an offline test for every behavior change.