aws-cryptographic-material-providers
AWS Cryptographic Material Providers Library for Python
Decision gist · record as of 2026-08-14
Yes, if you are building AWS-integrated applications that need encryption with centralized key management. The library is actively maintained, has no known vulnerabilities, and low install friction. Install with caution only if your license terms are unclear—verify the actual license before adopting in a commercial project, since the metadata does not declare it explicitly.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.11 or later; cryptography >= 43.0.1 and boto3 >= 1.35.42 must be installed.
- KMS-based keyrings are not thread-safe when shared across threads.
- Low friction installation as a pure Python wheel.
License · maintenance · safety
(unclear) — License treatment is unclear in the package metadata, so you should verify the actual license terms before adopting this in a commercial or copyleft-sensitive project.
last release 2026-02-23 (172 days)
0 known vulnerabilities (OSV.dev, 2026-08-14) · 540,368 downloads/mo, #6,105 on PyPI
Alternatives
Verify before relying
pip install aws-cryptographic-material-providers
from aws_cryptographic_material_providers.material_providers import MaterialProviders
client = MaterialProviders()
# Use client to create keyrings and crypto materials managers- Exact license terms and SPDX identifier (metadata shows 'unclear' treatment)
- Whether thread-safe keyring implementations with caching support are planned
- Performance characteristics and throughput limits for high-volume key derivation
What it is and what it does
This is AWS's cryptographic materials provider library for Python, designed to manage encryption keys and derived cryptographic material in AWS-integrated applications. It abstracts key management operations—including generation, derivation, and caching—and provides integration points with AWS KMS for key storage and rotation. The library is built on four internal AWS cryptography modules (dynamodb, kms, primitives, and standard-library) and exposes a MaterialProviders client that applications use to create keyrings and crypto materials managers.
The library targets modern Python (3.11+) and is actively maintained. It handles both simple and complex key hierarchies, supports envelope encryption patterns, and provides thread-safe client and manager implementations—though KMS-backed keyrings themselves are not thread-safe due to boto3 session constraints. It's intended for developers building encrypted storage, messaging, or data processing systems that need AWS-native key management without managing raw cryptographic keys directly.
Use it for
- Encrypt data at rest in S3 or DynamoDB using AWS KMS-managed keys without handling raw key material
- Implement envelope encryption in multi-tenant applications where each tenant's data is encrypted with derived keys
- Build encrypted messaging or event systems that cache cryptographic material to reduce KMS API calls
- Integrate encryption into data pipelines that require key rotation and audit trails via AWS KMS
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are building AWS-integrated applications that need encryption with centralized key management.
The library is actively maintained, has no known vulnerabilities, and low install friction. Install with caution only if your license terms are unclear—verify the actual license before adopting in a commercial project, since the metadata does not declare it explicitly.
Install
aws-cryptographic-material-providers on PyPI
Before you install
Low friction installation as a pure Python wheel. Actively maintained with recent releases. Requires cryptography >= 43.0.1 and boto3 >= 1.35.42 as runtime dependencies, plus system-level prerequisites for the cryptography library on some platforms.
Requires Python 3.11 or later; cryptography >= 43.0.1 and boto3 >= 1.35.42 must be installed. KMS-based keyrings are not thread-safe when shared across threads.
License in practice
License treatment is unclear in the package metadata, so you should verify the actual license terms before adopting this in a commercial or copyleft-sensitive project.
Quickstart
pip install aws-cryptographic-material-providers
from aws_cryptographic_material_providers.material_providers import MaterialProviders
client = MaterialProviders()
# Use client to create keyrings and crypto materials managers
Verify before relying
- Exact license terms and SPDX identifier (metadata shows 'unclear' treatment)
- Whether thread-safe keyring implementations with caching support are planned
- Performance characteristics and throughput limits for high-volume key derivation
Package facts
| License | Not declared unclear |
| Python support | Supports the current Python release <4.0.0,>=3.11.0 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesaws-cryptography-internal-dynamodbaws-cryptography-internal-kmsaws-cryptography-internal-primitivesaws-cryptography-internal-standard-library |
| Maintenance | Actively maintained 172 days since the last release |
| First released | |
| Downloads | 540,368 / month, #6,105 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Programming Language :: Python :: 3Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12 |
Evidence: aws_cryptographic_material_providers-1.11.2-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “cryptographic material providers”
- aws-cryptographic-material-providersProvides cryptographic material management and key derivation for…
- aws-encryption-sdkEncrypts and decrypts data using AWS KMS keys and keyrings,…
- hkdfImplements HMAC-based Key Derivation Function (HKDF) with…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also aws-encryption-sdk · PyKMIP · hkdf · aliyun-python-sdk-kms · dynamodb-encryption-sdk · google-cloud-kms · aws-encryption-sdk-cli · alibabacloud-kms20160120 · credstash