Go packages shared across Latere AI services: authentication and authorization, egress credential substitution, LLM wire-dialect translation, telemetry, audit events, object storage, transactional email, Postgres migrations, git and subprocess execution, and a set of small concurrency and text utilities. Every package is importable on its own, keeps its dependency surface small, and carries its own tests.
The module path is latere.ai/x/pkg; the source lives at
github.com/latere-ai/pkg.
go get latere.ai/x/pkgImport the package you need, not the module root:
import "latere.ai/x/pkg/md"The whole module is pure Go with no cgo, so it cross-compiles anywhere the Go toolchain does.
Parse frontmatter and render Markdown:
package main
import (
"fmt"
"log"
"latere.ai/x/pkg/md"
)
func main() {
src := []byte("---\ntitle: Notes\n---\n\n# Hello\n\nSome *text*.\n")
var meta struct{ Title string }
body, err := md.ParseInto(src, &meta)
if err != nil {
log.Fatal(err)
}
html, err := md.Render(body)
if err != nil {
log.Fatal(err)
}
fmt.Println(meta.Title)
fmt.Println(string(html))
}Call the Lux gateway with a typed request:
c := luxsdk.New("https://api.latere.ai/v1/models", luxsdk.WithAPIKey(key))
res, err := c.Generate(ctx, &luxsdk.Request{
Model: "claude-sonnet-5",
Messages: []luxsdk.Message{luxsdk.UserText("hello")},
})Each row links to the package directory. The full API, with examples, is on pkg.go.dev.
| Package | What it gives you |
|---|---|
agentweb |
A site's public pages for crawlers and AI agents: robots.txt with Content Signals usage preferences, a sitemap with hreflang alternates, llms.txt and a streamed llms-full.txt, and middleware that answers Accept: text/markdown with the page's Markdown twin, all rendered from one page index. Standard library only. See agentweb/README.md |
audit |
The canonical audit-event envelope, the Emitter interface products compose behind MultiEmitter, a stdout emitter, and redaction helpers. Storage adapters stay in each product |
authkit |
Authentication. The root holds the shared Identity type, the Authenticator interface, the grants a personal access token carries, and the middleware services share. authkit/jwt verifies RS256 and ES256 tokens offline against a cached JWKS; authkit/oidc is the OIDC relying party with cookie sessions, token refresh, and the login handlers; authkit/cli is the token store and device-code login for command-line clients; authkit/issuertest is a stub issuer for tests; authkit/conformance is the verification suite a service runs against its own authenticator |
authz |
The authorizer contract the open cores share: the request and decision envelope, a client with caching and fail-closed rules, the owner policy a self-hosted core falls back to, and a core's action table as data. A decision is narrowed by the grants the caller's credential carries. authz/server is the scaffold an authorization endpoint is written on, authz/stub a stub endpoint for test tiers, and authz/conformance the suite every endpoint passes |
drive |
Client for the Drive workspace HTTP contract: attach, materialize, write back, lease renewal, and paginated lists, with a bearer resolved per request and typed errors |
egress |
Credential substitution at an egress boundary: a workload holds an opaque placeholder, and the gateway swaps it for the real secret only toward the hosts the credential is scoped to. The substitution engine, static and minted secrets, an ingest API and client, JWT proxy authentication, and a TLS-terminating CONNECT gateway. egress/placeholder mints and recognizes placeholders with the standard library alone |
email |
Transactional mail over Mailgun or SMTP, with a log-only fallback; refuses header injection. Subjects and bodies stay with the calling service |
health |
The probe surface a service serves on its internal listener: /livez, /readyz with named checks, /version, and /metrics. Why two probes and how to move a service is in docs/health.md |
hostsandbox |
Runs a process on the operator's own machine inside an srt sandbox (Seatbelt on macOS, bubblewrap on Linux), detached, with output written where the process cannot reach it, and a handle that survives a restart. hostsandbox/hostsandboxtest is the contract every driver is held to |
llmdialect |
Translation between LLM wire dialects (Anthropic Messages, OpenAI Chat Completions, OpenAI Responses, and the Lux-native dialect) through a neutral intermediate representation, with an explicit loss report instead of silent drops. Standard library only. llmdialect/bridge translates requests, responses, and streams with no server in between; llmdialect/tokencount estimates input tokens without a tokenizer |
llmjson |
Repairs the JSON a model meant to send: strips a Markdown fence and escapes raw newlines and tabs inside strings, so a correct answer in the wrong encoding still decodes |
luxsdk |
Go client for the Lux gateway's native dialect: typed generate, streaming, and token counting, or the same calls straight to a provider. See luxsdk/README.md |
md |
YAML frontmatter parsing and GitHub Flavored Markdown to HTML. See md/README.md |
otel |
One-call OpenTelemetry setup for traces, metrics, and structured logs, HTTP server and client instrumentation, child spans, and a same-origin relay for browser telemetry. See otel/README.md |
pgxmigrate |
Applies embedded golang-migrate migrations and closes migrate's own connection pool afterward |
provenance |
Carries the person a call is for across service hops as W3C Baggage (initiator.sub, initiator.iss, entry) and puts it on spans, log lines, and audit records. Metadata only: it grants nothing |
s3 |
S3 REST client in the standard library: put, create-if-absent, conditional get, head, delete, prefixed listing, and presigned GET and PUT, signed with Signature Version 4 and retried under retry. s3/s3test is an in-process endpoint for tests that checks signatures and digests the way a provider does |
typesafeai |
Unofficial client for the TypeSafe API: one state evaluated against typed questions (a yes/no probability, a choice from a set, or a score against a rubric). The package name is typesafe |
verdict |
The decision vocabulary every decision point shares: allow, flag, ask and block in their order, composition that can only narrow (an unknown verdict counts as block), the never-more-than-ask rule on failure, and Decide, which applies a ceiling and random review sampling and returns the probability a person sees the action, so any decision source's error rate is estimable. Standard library only |
Smaller pieces with no product knowledge in them.
| Package | What it gives you |
|---|---|
atomicfile |
Write-then-rename file replacement, so a reader never observes a half-written file |
batch |
A non-blocking batching pump: producers add without blocking, and one goroutine flushes by size or interval and drains on shutdown |
bearer |
Reads the token from Authorization: Bearer with a case-insensitive scheme, and compares tokens in constant time |
cache |
Generic TTL cache with an optional LRU cap over every entry and an injectable clock |
circuitbreaker |
Two breakers: a lock-free closed, open, and half-open breaker for hot paths, and a mutex-based breaker with exponential backoff |
cmdexec |
Fluent subprocess builder, and a sequencer that rolls back completed steps when a later one fails |
dag |
Graph operations over adjacency lists: deterministic topological sort, cycle detection, reachability, longest path, edge reversal |
dircp |
Recursive directory copy |
envutil |
Typed environment reads with defaults: integers, bounded integers, durations, and the conventional boolean spellings |
errwriter |
A writer that remembers the first error, so a run of writes is checked once |
gitutil |
The git command line behind structured results and typed errors: worktrees, rebase with conflict recovery, stashes, branch discovery |
hostmatch |
One host allow-list rule: exact names and *. wildcards that match any subdomain depth but never the apex |
httpjson |
Strict JSON request decoding (unknown fields and trailing content rejected), response writing, and the {"error": {code, message, details}} envelope |
metrics |
Prometheus text-exposition registry with labeled counters, histograms, and scrape-time gauges, and no client-library dependency |
ndjson |
Reading and appending newline-delimited JSON files, and the terminal-result scan agent output parsers need |
pagination |
Cursor pagination over a pre-sorted slice |
pubsub |
Generic in-process fan-out hub with a bounded replay buffer, so a subscriber that reconnects picks up where it left off |
ratelimit |
Keyed token buckets with refill, burst, per-key rates, retry delay, and idle eviction that cannot reset a quota |
relpath |
Traversal-safe relative paths: validate, join under a base, and symlink-aware containment |
retry |
Bounded exponential backoff with jitter, and optional per-attempt deadlines under the caller's total budget |
routine |
Periodic fire-and-forget callbacks keyed by UUID, one timer each, with an injectable clock |
sanitize |
Rune-safe display truncation, byte-budget truncation that never splits a rune, slug generation, and slug validation |
semaphore |
Cancellable admission for concurrent work, with a wait deadline and an idempotent release |
statemachine |
Generic finite state machine that validates each transition against a table |
syncmap |
Type-safe sync.Map, with LoadOrStore for the per-key mutex idiom |
trackedwg |
Wait group that reports which labeled goroutines are still outstanding |
tree |
Generic rooted tree with parent-child links, a key index, and a walk |
uniq |
Order-preserving deduplication, a trim-and-drop-empties form for string lists, and a catalog merge that rejects a repeated key |
wait |
Cancellable sleep, ticker loop, and poll. wait/waittest polls a condition in a test until it holds |
watcher |
Event loop for a background goroutine woken by a signal, a ticker, or both, with an optional settle delay before it acts |
The module is at v0.x, and the API is not frozen: a minor version may carry
a breaking change. Pin an exact version and read its section of
CHANGELOG.md before upgrading; every tag has one, and a
breaking change says what to do about it. The module path and the package
layout are stable.
- pkg.go.dev: the API of every package.
agentweb,luxsdk,md, andotelcarry a usage guide beside the code.docs/health.md: the probe paths and how to adopt them.docs/writing/registers.md: the writing rule for everything a Latere product emits, and the canonical statement that every Latere repository points to.
Issues and pull requests are welcome. CONTRIBUTING.md says what belongs in this module, the bar a package meets, how to run the checks locally, and how a release is cut.