Four SDKs.
One contract.
Rust, TypeScript, Python, and Go. All generated from the same OpenAPI spec. Identical feature surface. Identical retry semantics. Identical telemetry hooks. Choose your stack — get the same Zaps.
Last published: 2026-04-08 · Next release window: 2026-04-22 · Owner: @l1feai/zaps-devrel
| Capability | Rust | TypeScript | Python | Go |
|---|---|---|---|---|
| API key auth | ✓ | ✓ | ✓ | ✓ |
| OAuth 2.0 client credentials | ✓ | ✓ | ✓ | ✓ |
| JWT bearer | ✓ | ✓ | ✓ | ✓ |
| mTLS | ✓ | ✓ | ✓ | ✓ |
| Server-Sent Events / streaming | ✓ | ✓ | ✓ | ✓ |
| Auto retries · exp backoff + jitter | ✓ | ✓ | ✓ | ✓ |
| Rate-limit headers + auto throttle | ✓ | ✓ | ✓ | ✓ |
| Cursor pagination | ✓ | ✓ | ✓ | ✓ |
| Auto-pagination iterators | ✓ | ✓ | ✓ | ✓ |
| Webhook signature verification | ✓ | ✓ | ✓ | ✓ |
| Multipart upload | ✓ | ✓ | ✓ | ✓ |
| Async / concurrent requests | ✓ | ✓ | ✓ | ✓ |
| Custom HTTP client / proxy | ✓ | ✓ | ✓ | ✓ |
| Fully-typed models | ✓ | ✓ | ✓ | ✓ |
| OpenTelemetry hooks | ✓ | ✓ | ✓ | ✓ |
| Request/response middleware | ✓ | ✓ | ✓ | ✓ |
| Idempotency key support | ✓ | ✓ | ✓ | ✓ |
Source of truth · regenerated in CI on every release · owner @l1feai/zaps-devrel
SOC 2 Type II
Trust report and current control mapping available on request. Email security@l1fe.ai.
Package signing
Every published artifact (cargo, npm, PyPI, pkg.go.dev) is signed and verifiable with cosign.
SLSA Level 3
All SDK builds run on isolated GitHub Actions runners with SLSA L3 provenance attestation.
SBOM
A complete SBOM ships with every SDK release at github.com/l1feai/zaps/releases.
Dependency scanning
Critical CVEs block merge. High-severity findings ship a patch within one business day.
Responsible disclosure
Email security@l1fe.ai or report via the program at hackerone.com/l1feai.
Issues are filed at github.com/l1feai/zaps/issues. Enterprise customers get a dedicated Slack channel and a named support engineer with response-time commitments below.