Route Python and native clients through a World
A Node preload does not intercept Python, curl, Go or a native binary. Those clients must honor the World's proxy and session CA, or a vendor-supported endpoint override. Being launched in a World does not by itself prove every network call was routed.
A Python request to the real vendor hostname
Use Node 22.6 or newer, npm and Python 3 in an empty directory. The example first creates a customer using the real Node SDK, then reads it from Python through the scoped HTTPS proxy.
{
"name": "acme-web",
"private": true,
"type": "module",
"dependencies": {
"stripe": "17.7.0"
},
"devDependencies": {
"@volter/world": "3.0.63",
"@volter/twin-stripe": "3.0.1"
}
}STRIPE_SECRET_KEY=import assert from 'node:assert/strict';
import Stripe from 'stripe';
const stripe = new Stripe(process.env.STRIPE_SECRET_KEY, { maxNetworkRetries: 0 });
const made = await stripe.customers.create({ email: 'ada@example.com', name: 'Ada' });
assert.equal((await stripe.customers.retrieve(made.id)).email, 'ada@example.com');
assert.equal(made.created, Date.parse('2026-01-15T12:00:00Z') / 1000);
console.log('create, read and frozen timestamp passed');import json, os, ssl, urllib.request
proxy = os.environ.get('HTTPS_PROXY') or os.environ.get('https_proxy')
ca = os.environ.get('CURL_CA_BUNDLE') or os.environ.get('SSL_CERT_FILE')
if not proxy or not ca: raise RuntimeError('Expected the World proxy and its session CA')
client = urllib.request.build_opener(urllib.request.ProxyHandler({'https': proxy}), urllib.request.HTTPSHandler(context=ssl.create_default_context(cafile=ca)))
request = urllib.request.Request('https://api.stripe.com/v1/customers', headers={'Authorization': 'Bearer ' + os.environ['STRIPE_SECRET_KEY']})
with client.open(request) as response: customers = json.load(response)
assert any(c.get('email') == 'ada@example.com' for c in customers['data'])
print('Python real-hostname request read the seeded customer')npm install
npx volter world init --name native-client --twins stripe
npx volter world up
npx volter world clock set 2026-01-15T12:00:00Z
npx volter world run -- node check.mjs
npx volter world run -- python3 read-customer.pyPython real-hostname request read the seeded customerThe Python code explicitly uses the inherited proxy and its CA. It calls api.stripe.com, keeps TLS verification enabled, and receives the same stored customer. It uses only Python's standard library. Do not print the proxy environment, bearer keys or CA custody into a bug report.
npx volter world log
npx volter world downOther clients
| Client behavior | Configure | Verify |
|---|---|---|
Honors HTTPS_PROXY and a CA path | Run through the World; select that client's supported trust variable or explicit CA option | A vendor request and expected state/log result |
| Has its own SDK/CLI endpoint override | Use the override declared by the twin, such as AWS_ENDPOINT_URL | The selected endpoint, SDK result and log |
| Ignores proxy variables | Set its documented proxy/CA options, or a supported explicit endpoint | Do not infer routing from the parent shell |
| Uses raw sockets, native DNS or an unsupported transport | Use the appropriate enforced Machine/executor boundary when isolation is required | Actual boundary evidence; cooperative sandbox alone is insufficient |
npx volter world shell opens a subshell with World routing. eval "$(npx volter world activate)" activates a compatible shell; deactivate restores it. Prefer world run for bounded scripts so the caller's shell is not left activated. Closing a shell does not tear down the World.
A CA trusted through environment variables is scoped to cooperating clients, not installed into the system trust store. Never turn off TLS verification to get a request through. Sandbox mode refuses untwinned destinations in cooperating clients, but cannot constrain a binary that ignores its mediation. See transport coverage, CLI for remote commands, and recovery for diagnostic commands.