veloce
Health Warn
- License — License: MIT
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 5 GitHub stars
Code Pass
- Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Pass
- Permissions — No dangerous permissions requested
No AI report is available for this listing yet.
Async Python web framework where one route definition drives HTTP, OpenAPI and MCP tools. ASGI-native, written from scratch, batteries included.
Veloce
Async Python web framework where one route definition drives an HTTP endpoint, an OpenAPI operation and an MCP tool — ASGI-native, batteries included.
Documentation: veloceframework.com
Source code: https://github.com/Lokesh-Tallapaneni/veloce
Veloce framework (PyPI: veloceframework) is an ultra-fast async Python web framework — ASGI-native and batteries-included.
Veloce is a from-scratch async Python web framework. The router,
request/response pipeline, dependency injection system, OpenAPI
generator, WebSocket layer, and test client are all in-tree — not
wrappers around an existing stack.
Position
Veloce is a from-scratch async Python web framework — not a wrapper around Starlette, FastAPI, or Flask. It provides FastAPI-style typed dependency injection, Pydantic v2 request/response validation, OpenAPI 3.1 schema generation, WebSocket support, and Flask-compatible helpers (g, flash, blueprints, session) in a single tree. It is built on a radix-tree router, an in-memory test client, and built-in CORS/CSRF/session/rate-limit/security-headers middleware. An external security review of the request path is planned ahead of 1.0; until then, treat it as pre-production software.
Key design points
- Async-first handlers.
async defhandlers run directly on the
event loop; syncdefhandlers are supported transparently and run in
a thread-pool executor so they do not block it. - Precompiled dispatch. Handler signatures are inspected once at
registration into aHandlerPlan; the per-request hot path performs
no reflection. - Radix-tree routing with typed path converters (
int,float,string,uuid,path,date,datetime,time,timedelta,decimal,any, plus custom). - Typed dependency injection via
Depends,Security,SecurityScopes, includingyield-style dependencies with teardown. - OpenAPI 3.1 generated from Pydantic models, served through
Swagger UI and ReDoc out of the box. - In-memory test client drives the real ASGI surface — no sockets,
no separate server process.
Requirements
Python 3.10+.
Veloce depends on orjson, httptools, pydantic v2, python-multipart,multidict, jinja2, and uvloop on non-Windows platforms.
Installation
pip install veloceframework
That alone serves, via the built-in app.run() server. For a deployment, thestandard extra adds uvicorn, brotli and msgspec:
pip install "veloceframework[standard]"
The installed package exposes the veloce import:
from veloce import Veloce
Example
Create main.py:
from veloce import Veloce
app = Veloce()
@app.get("/")
async def index() -> dict[str, str]:
return {"hello": "world"}
@app.get("/items/{item_id:int}")
async def read_item(item_id: int) -> dict[str, int]:
return {"item_id": item_id}
Run it:
veloce run main:app
veloce run serves under uvicorn when it is installed and falls back to the
built-in server, which needs no extra dependencies. To pin the built-in server
regardless, call app.run().
uvicorn is an optional extra — install it (pip install veloceframework[uvicorn])
to serve under it or any other ASGI server, or use app.run() / the gunicornVeloceWorker:
uvicorn main:app
Open http://127.0.0.1:8000/items/42 to see {"item_id": 42}, or
http://127.0.0.1:8000/docs for the interactive OpenAPI UI.
Feature surface
| Area | Highlights |
|---|---|
| Routing | radix tree, path converters, blueprints with nesting, subdomain routing, host constraints |
| Requests | streaming bodies, multipart, JSON, MultiDict query/headers/cookies, rich URL/header accessors |
| Responses | JSONResponse, HTMLResponse, StreamingResponse, FileResponse, ETag/Last-Modified |
| Dependency inj. | Depends, Security, SecurityScopes, Annotated[T, Depends()], yield + teardown |
| Validation | Pydantic v2 query / path / header / cookie / body, structured 422 errors |
| OpenAPI | OpenAPI 3.1, Swagger UI, ReDoc, security schemes, webhooks, callbacks, operation_id |
| WebSockets | full ASGI surface, dependency injection, subprotocol negotiation (under an ASGI server), typed iter helpers |
| Middleware | CORS, compression (zstd/brotli/gzip), TrustedHost, HTTPSRedirect, ProxyFix, Session, CSRF, CSP, security headers, conditional GET, request IDs, logging, BaseHTTPMiddleware |
| Templating | Jinja2 with url_for / g / current_app globals, async render, context processors |
| Sessions | signed cookies, server-side backend, permanent_lifetime, secret rotation |
| Streaming | Server-Sent Events (EventSourceResponse, ServerSentEvent), streamed request bodies |
| Signals | request_started / request_finished / got_request_exception and the app-context pair |
| Security | password hashing (hash_password, is_strong_password), signing, JWT, OAuth2 flows |
| Rate limiting | FixedWindow / SlidingWindow / TokenBucket, per-route @rate_limit, Redis backend |
| Caching | Cache / InMemoryCache, the @cached decorator, Redis backend |
| Agents (MCP) | expose routes as Model Context Protocol tools, resources, prompts; HTTP / SSE / stdio transports |
| Testing | in-memory TestClient, multipart, cookies, follow-redirects, session_transaction |
| Tooling | veloce new / generate scaffolding, run, routes, check, mcp, shell |
The full Tier 0/1/2 feature matrix and per-feature design notes live indocs/.
Project status
Veloce follows semantic versioning: the public
API surface — the names exported from veloce/__init__.py — is what each
release commits to. The current version is shown by the PyPI badge above.
Sponsor
Veloce is developed in the open. If it is useful to you, you can support its
continued development through
GitHub Sponsors.
License
MIT. See LICENSE.
Reviews (0)
Sign in to leave a review.
Leave a reviewNo results found