ansible-vault
R/W an ansible-vault yaml file
Decision gist · record as of 2026-08-14
Yes, if you need to work with Ansible vault files from Python code. The package is actively maintained, has low install friction, and no known vulnerabilities. However, the GPL-3.0-or-later copyleft license means you cannot use it in proprietary closed-source projects without licensing the entire work under GPL.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Low friction installation with only two runtime dependencies (ansible-core and PyYAML).
- Actively maintained with a recent commit in April 2026 and stable production status.
License · maintenance · safety
GPL-3.0-or-later (copyleft) — Licensed under GPL-3.0-or-later (copyleft). Any derivative work or distribution must also be licensed under a compatible GPL version, which may restrict use in proprietary projects.
last release 2025-05-15 (456 days) · last repo commit 2026-04-05 · 54 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 204,499 downloads/mo, #9,605 on PyPI
Alternatives
Verify before relying
pip install ansible-vault
from ansible_vault import Vault
vault = Vault('password')
data = vault.load(open('vault.yml').read())
vault.dump(data, open('vault.yml', 'w'))- Whether the package works with Ansible versions beyond those implied by ansible-core dependency
- Performance characteristics when handling large vault files
- Whether password handling supports environment variables or external key management systems
What it is and what it does
ansible-vault is a Python library for reading and writing Ansible vault-encrypted YAML files outside of the Ansible CLI. It wraps the vault encryption/decryption functionality, letting you load encrypted vault data into Python objects and serialize modified data back to encrypted vault format.
The package depends on ansible-core and PyYAML, making it suitable for automation scripts, configuration management tools, or applications that need to work with Ansible vault files programmatically. It's been actively maintained since 2015 and is marked production-stable, with recent updates through 2026.
Use it for
- Decrypt Ansible vault files in Python scripts to access secrets without invoking the Ansible CLI
- Automate vault file updates by loading, modifying, and re-encrypting YAML configuration data
- Integrate Ansible vault decryption into CI/CD pipelines or deployment automation tools
- Build configuration management tools that need to read and write encrypted Ansible vault data
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need to work with Ansible vault files from Python code.
The package is actively maintained, has low install friction, and no known vulnerabilities. However, the GPL-3.0-or-later copyleft license means you cannot use it in proprietary closed-source projects without licensing the entire work under GPL.
Install
ansible-vault on PyPI
Before you install
Low friction installation with only two runtime dependencies (ansible-core and PyYAML). Actively maintained with a recent commit in April 2026 and stable production status.
License in practice
Licensed under GPL-3.0-or-later (copyleft). Any derivative work or distribution must also be licensed under a compatible GPL version, which may restrict use in proprietary projects.
Quickstart
pip install ansible-vault
from ansible_vault import Vault
vault = Vault('password')
data = vault.load(open('vault.yml').read())
vault.dump(data, open('vault.yml', 'w'))
Verify before relying
- Whether the package works with Ansible versions beyond those implied by ansible-core dependency
- Performance characteristics when handling large vault files
- Whether password handling supports environment variables or external key management systems
Package facts
| License | GPL-3.0-or-later copyleft |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagesansible-corePyYAML |
| Maintenance | Actively maintained 456 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 204,499 / month, #9,605 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13 |
Evidence: ansible_vault-4.1.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “ansible vault yaml encryption”
- ansible-vaultReads and writes Ansible vault-encrypted YAML files programmatically,…
- hvachvac is a Python client library for HashiCorp Vault that enables…
- skyflowA Python SDK for securely integrating with Skyflow Vault to tokenize,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also pyAesCrypt · pyzipper · crypto · kasa-crypt · aws-encryption-sdk-cli · dynamodb-encryption-sdk · onepassword · keyrings.cryptfile · msoffcrypto-tool · dynaconf