eggfetch
eggfetch is a Rust-native async HTTP client engine (tokio + hyper) with Python bindings and a CLI. There is exactly one networking implementation, living entirely in eggfetch-core plus the small eggfetch-http-connect CONNECT wire primitive it owns; the Python sync API blocks on the async engine while releasing the GIL, and the async API integrates with asyncio.
Features
- HTTP/1.1, HTTP/2, HTTP/3 — ALPN negotiation; HTTP/3 over QUIC is experimental (guide)
- Streaming — response bodies stream without eager buffering (
bytes_stream(),text_lines()), with trailers after EOF (guide) - Pooling and timeouts — per-origin connection pools, phase-aware timeouts (pool/connect/write/read/total), and transport metrics (pool/timeouts)
- TLS — rustls with per-client crypto providers, custom or additive CA roots, mTLS client certs, version policy, and verification toggle (TLS)
- Proxy — HTTP forwarding, HTTPS CONNECT, proxy auth, per-request override,
NO_PROXY, SOCKS5, and UDS routes (proxy). CONNECT wire bytes live in the smalleggfetch-http-connectcrate (no sockets/TLS/retry) consumed byeggfetch-corevia theproxyfeature. - Cookies, auth, multipart — RFC 6265 jar, Basic/Bearer with redaction, streaming multipart uploads (cookies)
- Retries, redirects, and routing — policy-driven backoff with
Retry-After, replayable-body redirect handling (retry). Retry/redirect/Basic are coarse Cargo capabilities (logical-retry,redirects,basic-auth); advanced routing (custom Dialer, resolved-target/SNI, socket options, UDS) isadvanced-routing: the leanstandard-http1+tls-rustlsprofile omits both for Bearer-only single-attempt standard-route clients whilehttp1/http2/default retain current behavior. - Compression — feature-gated streaming gzip/brotli/zstd/deflate with zip-bomb limits (compression)
- Native Rust JSON (opt-in) —
RequestBuilder::json()/Response::json()via thejsonfeature (guide) - Python API — requests/HTTPX-compatible sync and async interfaces (guide), lazy request bodies, PEP 561 typing, plus versioned
eggfetch.compat.httpx(0.28.1) andeggfetch.compat.httpx2(2.12.0) facades (compatibility) - Upgrades — 101 responses expose an owned
network_stream(WebSocket/SSE building blocks); CONNECT tunnels stay body-iterator only - CLI — streaming output, machine-readable formats, shell completions (guide)
- C ABI and Node.js prototype — opaque-handle FFI plus an experimental N-API wrapper (ffi-and-node)
Installation
Python:
Rust:
[]
= "0.1"
The default features are the secure HTTP/1.1 client with Rustls and native roots. See the feature profile matrix for minimal, deterministic, and embedded recipes. Low-level embedding without the url/idna/ICU closure selects native-http1 (or native-http2) without high-level-url and uses Client::execute_http_body with a caller-owned http::Uri (callers own IDNA/punycode conversion). The lean high-level recipe (standard-http1 + tls-rustls, without advanced-routing or the logical-retry/redirects/basic-auth policy bundle) keeps the URL/request/response conveniences, Bearer auth, timeouts, body bounds, pooling, TLS, and typed failures while dispatching once over the standard route and returning 3xx without following.
CLI:
Usage -- Python
=
=
=
= await
= await
=
Versioned HTTPX-compatible facades over the same engine:
# HTTPX 0.28.1 surface
# httpx2 2.12.0 surface
See docs/python/guide.md for the full Python API reference.
The native package supports Python 3.10–3.14 and ships py.typed stubs for its public API. Client and the top-level sync helpers accept lazy sync content= iterables (async-only iterables are rejected before dispatch); AsyncClient additionally accepts lazy async iterables, pulled only as the transport asks for them. eggfetch._native is a private implementation module — import from eggfetch.
Usage -- Rust
use Client;
use StreamExt;
async
The opt-in json feature adds RequestBuilder::json() / Response::json() Serde helpers. For a private CA in addition to the selected native or WebPKI roots, use the additive TLS methods:
let tls = builder
.additional_ca_certificate_path?
.build;
let client = builder.tls_config.build;
additional_ca_certificate_* augments the base trust store; ca_certificate_* replaces it. Advanced embedding — custom dialers, direct/proxy address pinning, detailed failure introspection, frame-level bodies, the Tower service adapter, and physical-connection guards — is covered in docs/rust/guide.md.
Usage -- CLI
# GET request
# POST JSON
# With authentication
# Streaming download
# Machine-readable output
See docs/cli/guide.md for the full CLI reference.
Examples
Runnable starting points (each takes an optional base URL argument, default https://httpbin.org):
crates/eggfetch-core/examples/quickstart.rs— core client: configured GET/POST, timeout override, auth, streaming (cargo run -p eggfetch-core --example quickstart)examples/python_sync.py— sync client, JSON POST, streaming downloadexamples/python_async.py— async client with concurrent requests
More patterns are in docs/cookbook/.
HTTPX Compatibility
Two versioned, independent facades over the single Rust engine — eggfetch.compat.httpx (0.28.1) and eggfetch.compat.httpx2 (2.12.0, adds FunctionAuth, Origin/URL.origin, QUERY, SSE, optional WebSocket).
See docs/reference/compatibility.md for the full feature matrix and retained differences.
Documentation
| Section | Description |
|---|---|
| getting-started/ | Installation and quickstart guide |
| concepts/ | Architecture, lifecycle, timeouts, streaming, cookies, auth, proxy, TLS |
| rust/guide.md | Rust API guide with examples |
| python/guide.md | Python sync/async API guide |
| cli/guide.md | CLI reference and usage guide |
| migration/ | Migration guides from requests and HTTPX |
| cookbook/ | Practical runnable examples |
| reference/ | Compatibility matrix, feature matrix, error reference |
| security/ | Security guidelines and troubleshooting |
| architecture/ | Internal architecture documentation |
| ffi/ | C ABI and FFI binding guide |
Security
- Dependency auditing: run the live preflight with
./scripts/check_security.shbefore publication - Secret redaction: all
Debug/Display/error output redacts credentials, cookies, bearer tokens, and proxy passwords - Threat model: see docs/architecture/threat-model.md
- Vulnerability reporting: see SECURITY.md
License
eggfetch is licensed under the MIT License.
MSRV
The minimum supported Rust version is 1.89, declared in workspace.package.rust-version and checked in extended validation with the exact 1.89.0 toolchain. rust-toolchain.toml pins the stable channel for normal development.